spring-projects/spring-security · error · IllegalArgumentException
Unable to resolve the Client Registration Identifier. It…
Error message
Unable to resolve the Client Registration Identifier. It must be provided via @RegisteredOAuth2AuthorizedClient("client1") or @RegisteredOAuth2AuthorizedClient(registrationId = "client1"). What it means
@RegisteredOAuth2AuthorizedClient argument resolution requires an explicit registration id (value or registrationId attribute) or enough context (e.g. a current client via @CurrentOAuth2Client or default client registration). resolveArgument throws IllegalArgumentException when resolveClientRegistrationId returns empty.
Solutions
- Pass the registration id explicitly: @RegisteredOAuth2AuthorizedClient("client1")
- Configure a default via OAuth2AuthorizedClientArgumentResolver.setDefaultClientRegistrationId or @RegisteredOAuth2AuthorizedClient(registrationId="client1")
- Ensure a single ClientRegistration exists or set the default when only one client is configured and you rely on inference
Example fix
// before
public String index(@RegisteredOAuth2AuthorizedClient OAuth2AuthorizedClient client)
// after
public String index(@RegisteredOAuth2AuthorizedClient("client1") OAuth2AuthorizedClient client) Defensive patterns
Strategy: validation
Validate before calling
String registrationId = authorizedClient.value(); Assert.hasText(registrationId, "@RegisteredOAuth2AuthorizedClient requires an explicit registrationId");
Prevention
- Always pass the registration id explicitly to @RegisteredOAuth2AuthorizedClient
- Set a default client registration id on the resolver when using a single client
- Check annotation attributes after refactors
When it happens
Trigger: A controller method declares @RegisteredOAuth2AuthorizedClient without value/registrationId and no default or context-based registration can be inferred.
Common situations: Copy-pasted annotations with the placeholder stripped; refactor removing the annotation attribute; using the resolver without a setDefaultClientRegistrationId in a multi-client setup.
Understand the failure class
Background: "missing required argument" and "the following required arguments were not provided": what required-argument errors mean and how to fix them — this error's family across 20 libraries.
Related errors
- An error occurred reading the OAuth 2.0 Client…
- An error occurred reading the OAuth 2.0 Device…
- An error occurred reading the OAuth 2.0 Error
- An error occurred reading the Token Introspection Response…
- An error occurred writing the OAuth 2.0 Authorization…
AI-assisted analysis of spring-projects/spring-security@96852e8860 (2026-09-10).
Data as JSON: /api/errors/7c5505acdb9efd93.
Report an issue: GitHub.
Appendix: source
Thrown at oauth2/oauth2-client/src/main/java/org/springframework/security/oauth2/client/web/method/annotation/OAuth2AuthorizedClientArgumentResolver.java:113
Assert.notNull(clientRegistrationRepository, "clientRegistrationRepository cannot be null");
Assert.notNull(authorizedClientRepository, "authorizedClientRepository cannot be null");
this.authorizedClientManager = new DefaultOAuth2AuthorizedClientManager(clientRegistrationRepository,
authorizedClientRepository);
}
@Override
public boolean supportsParameter(MethodParameter parameter) {
Class<?> parameterType = parameter.getParameterType();
return (OAuth2AuthorizedClient.class.isAssignableFrom(parameterType) && (AnnotatedElementUtils
.findMergedAnnotation(parameter.getParameter(), RegisteredOAuth2AuthorizedClient.class) != null));
}
@Override
public @Nullable Object resolveArgument(MethodParameter parameter, @Nullable ModelAndViewContainer mavContainer,
NativeWebRequest webRequest, @Nullable WebDataBinderFactory binderFactory) {
String clientRegistrationId = this.resolveClientRegistrationId(parameter);
if (!StringUtils.hasLength(clientRegistrationId)) {
throw new IllegalArgumentException("Unable to resolve the Client Registration Identifier. "
+ "It must be provided via @RegisteredOAuth2AuthorizedClient(\"client1\") or "
+ "@RegisteredOAuth2AuthorizedClient(registrationId = \"client1\").");
}
Authentication principal = this.securityContextHolderStrategy.getContext().getAuthentication();
if (principal == null) {
principal = ANONYMOUS_AUTHENTICATION;
}
HttpServletRequest servletRequest = webRequest.getNativeRequest(HttpServletRequest.class);
HttpServletResponse servletResponse = webRequest.getNativeResponse(HttpServletResponse.class);
Assert.notNull(servletRequest, "HttpServletRequest is required for OAuth2 authorized client resolution");
Assert.notNull(servletResponse, "HttpServletResponse is required for OAuth2 authorized client resolution");
// @formatter:off
OAuth2AuthorizeRequest authorizeRequest = OAuth2AuthorizeRequest
.withClientRegistrationId(clientRegistrationId)
.principal(principal)
.attribute(HttpServletRequest.class.getName(), servletRequest)
.attribute(HttpServletResponse.class.getName(), servletResponse)
.build();View on GitHub (pinned to 96852e8860)